Internet security and the case of Bank of America
Arie Segev, Jaana Porra, Malu Roldan · Communications of the ACM · 1998
This article addresses some organizational and technical issues facing companies considering the Internet for critical business transactions. The article focuses on the issue of Internet security citing the case of Bank of America Corp. (BofA). Until recently most banks trusted their critical electronic business transactions to external value-added network (VAN) providers. Today, however, the Internet is often proposed as an alternative to VAN's as the transport medium based on the perceived low cost of the Internet and the rapidly developing Internet security infrastructure. The case presented here shows how these organizational issues emerged in a two-year project study conducted at the BofA. The purpose of this project was to demonstrate the feasibility of exchanging secure payment transactions over the Internet with BofA's customer-the Lawrence Livermore National Laboratory. Based on the lessons from this study, we suggest that an organization's Internet components must be an integral part of corporatewide information system security management and may require a reorganization of the Internet-related business units. Moreover, adopting the Internet for critical business transactions may not be as cost effective as technical comparisons with alternative transport media providers leads one to believe. Project was the creation of a unit called Interactive Banking. The purpose of the new business unit is to continue to experiment with the Internet and related technologies in order to develop viable business ideas based on new technologies. The aim was to combine relevant technology resources, marketing, product development, customer service talent, and security expertise into a single unit. Today, BofA has a better understanding of the scope of change associated with commerce over the Internet and a new business unit to manage the process.